Skip to content

Latest commit

 

History

History
347 lines (218 loc) · 14 KB

File metadata and controls

347 lines (218 loc) · 14 KB

Apiflow Privacy Policy

Last Updated: January 9, 2026


Overview

Apiflow (hereinafter referred to as "we", "us", or "the Product") is a completely free API development and testing tool. We value your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and protect your information.

This Privacy Policy applies to all versions of Apiflow, including desktop applications (Windows, macOS, Linux), web online version, and self-hosted deployments.


1. Data We Collect

1.1 Data You Provide

When you use Apiflow, you may provide us with the following information:

  • Account Information: If you choose to register an account, we collect your username, email address, and password (encrypted storage)
  • Project Data: API projects, interface definitions, documentation, variables, environment configurations you create
  • Team Collaboration Data: Team names, member information, permission settings, operation history
  • Feedback Information: Content you provide when submitting issue reports or feedback

1.2 Automatically Collected Data

To provide and improve our services, we may automatically collect:

  • Usage Data: Application version, operating system type and version, feature usage
  • Diagnostic Data: Error logs, crash reports, performance metrics
  • Device Information: Device identifiers, hardware model, network connection type

1.3 Locally Stored Data

Apiflow follows a Local-First design philosophy. The following data is primarily stored on your local device:

  • IndexedDB Data: API projects, interface definitions, request history, response cache, variable configurations, Cookie information
  • Local Storage Data: User preferences, application configurations, interface state
  • Temporary Files: Temporary files for import/export, uploaded attachments

1.4 Offline Mode

In offline mode, all data is stored entirely on your local device and is not transmitted to any server. You can switch between offline and online modes at any time.


2. How We Use Data

2.1 Provide and Maintain Services

  • Provide core functions such as API testing, Mock services, WebSocket connections
  • Save and synchronize your project data (only in online mode)
  • Implement team collaboration and permission management features
  • Process your account login and authentication

2.2 Improve and Develop Products

  • Analyze product usage to understand user needs
  • Diagnose and fix technical issues
  • Develop new features and improve existing ones
  • Optimize product performance

2.3 Communication and Support

  • Respond to your inquiries and support requests
  • Send important product update notifications
  • Provide technical documentation and help information

2.4 Security and Compliance

  • Detect and prevent fraud, abuse, or illegal activities
  • Protect user accounts and data security
  • Comply with legal and regulatory requirements

3. Data Storage and Security

3.1 Data Storage Location

  • Offline Mode: All data is stored on your local device (IndexedDB, LocalStorage)
  • Online Mode: Project data is stored on our servers (located in China), with local copies maintained
  • Self-Hosted Deployment: All data is fully controlled by you and stored on your designated server

3.2 Security Measures

We take the following measures to protect your data:

  • Data Transmission Encryption: Use HTTPS/TLS protocol to encrypt all network transmissions
  • Password Encryption: User passwords are stored using industry-standard encryption algorithms
  • Access Control: Strict permission management and authentication mechanisms
  • Regular Backups: Regular data backups to prevent data loss
  • Security Audits: Regular security audits and vulnerability scans

3.3 Data Retention

  • Active Accounts: We will retain your data as long as your account is active
  • Deleted Data: Projects and data you delete will be permanently deleted after 30 days
  • Inactive Accounts: Accounts that have not been logged into for more than 2 years may be considered inactive, and we may delete related data
  • Local Data: You can clear all locally stored data at any time

4. Data Sharing and Disclosure

4.1 We Do Not Sell Your Data

We do not sell, rent, or trade your personal data to third parties.

4.2 Limited Data Sharing

We only share your data in the following circumstances:

  • With Your Consent: When we have your explicit consent
  • Team Collaboration: Share project data with other members of your team (based on permissions you set)
  • Service Providers: With third-party service providers who help us operate our services (such as cloud service providers, CDN providers), who are contractually bound to protect your data
  • Legal Requirements: Disclosure required by laws and regulations, judicial orders, or government agency requests

4.3 Business Transfers

If we are involved in a merger, acquisition, or asset sale, your data may be transferred. We will notify you before your data becomes subject to a different privacy policy.


5. Your Rights and Choices

5.1 Access and Control Data

You have the right to:

  • Access Data: View personal data we have collected about you
  • Correct Data: Update or correct inaccurate information
  • Delete Data: Request deletion of your account and related data
  • Export Data: Export your project data in OpenAPI 3.0, JSON, and other formats
  • Withdraw Consent: Withdraw consent you previously granted for data processing

5.2 Choose Offline Mode

You can choose to use offline mode entirely, in which:

  • All data is stored only on your local device
  • No data is sent to servers
  • You have complete control over your data

5.3 Data Migration

We support the standard OpenAPI 3.0 format, allowing you to:

  • Export your data at any time
  • Migrate to other compatible tools (Postman, Insomnia, Hoppscotch, etc.)
  • Migrate data between different Apiflow instances

6. Cookies and Similar Technologies

6.1 Cookies We Use

We use Cookies and similar technologies to:

  • Maintain your login status
  • Remember your preference settings
  • Analyze product usage
  • Provide personalized experiences

6.2 Managing Cookies

You can manage or delete Cookies through your browser settings. However, please note that disabling Cookies may affect the normal use of certain features.

6.3 Local Storage

In addition to Cookies, we also use browser LocalStorage and IndexedDB storage features. You can clear this data through your browser's developer tools or in-app settings.


7. Google Analytics Usage

7.1 What We Collect

When you enable analytics in the web version of Apiflow (online mode only), we use Google Analytics to collect anonymous usage data, including but not limited to:

  • Page Views: Pages you visit and time spent
  • Application Events: Feature usage (e.g., sending HTTP requests, creating projects, starting Mock servers)
  • Technical Information: Browser type, operating system, screen resolution
  • User Journey: Navigation paths and click patterns

Important Notes:

  • All data collected is anonymous and cannot identify you personally
  • We do NOT collect any sensitive information such as API request content, response data, authentication tokens, or API endpoint URLs
  • We do NOT collect any project-specific data or content you create
  • Analytics is ONLY active when you explicitly enable it in settings

7.2 How to Control Google Analytics

Opt-Out by Default: Analytics is disabled by default for new users. You need to explicitly enable it in application settings.

Easy to Disable: You can enable or disable analytics at any time through:

  1. Navigate to Settings → Common Settings → Application Configuration
  2. Toggle the "Help us improve product experience" switch
  3. Changes take effect immediately without restarting the application

Automatic Disabling: Analytics is automatically disabled in the following scenarios:

  • Development mode
  • Offline mode
  • Desktop application (Electron version)
  • When you explicitly disable it in settings

7.3 Data Processing

  • Third-Party Service: Google Analytics is operated by Google LLC, subject to Google's Privacy Policy
  • Data Retention: Google Analytics data is retained according to Google's standard data retention policy
  • Data Location: Analytics data may be processed and stored on Google's servers worldwide
  • No Cross-Site Tracking: We only use Google Analytics within Apiflow and do not track your activities on other websites

7.4 Purpose of Collection

We use collected analytics data to:

  • Understand which features are most/least used
  • Identify and fix potential issues
  • Improve user interface and experience
  • Prioritize feature development
  • Monitor application performance and stability

We Never:

  • Sell analytics data to third parties
  • Use analytics data for advertising purposes
  • Link analytics data to your personal identity
  • Collect content of your API projects or requests

8. Third-Party Services

8.1 AI Services

If you use Apiflow's AI Agent feature, you can configure your own Large Language Model (LLM) service. Your AI conversation data will be sent to the AI service provider you configure. We do not collect or store your AI conversation content unless you actively save it to your project.

Please review the privacy policies of the AI service providers you use to understand how they handle your data.

8.2 Google Analytics

As described in Section 7, we use Google Analytics to collect anonymous usage statistics (web version only, when explicitly enabled). Google Analytics is provided by Google LLC and subject to Google's privacy policies.

8.3 Import/Export Features

When you import data from other tools (such as Postman), we only process files you actively select and do not access other data on your device.


9. Children's Privacy

Apiflow is not directed at children under 13 years of age. We do not knowingly collect personal information from children under 13. If we discover that we have collected personal information from a child, we will immediately delete such information.


10. International Data Transfers

If you use Apiflow outside of China, your data may be transferred to servers within China. We will ensure compliance with applicable data protection laws.

Google Analytics: If you enable Google Analytics, your usage data will be processed by Google's global infrastructure and may be transferred internationally. This is subject to Google's privacy policies and data processing terms.

For self-hosted deployments, data is stored entirely on your own servers and does not involve cross-border transfers.


11. Changes to Privacy Policy

We may update this Privacy Policy from time to time. The updated policy will be posted on this page with the "Last Updated" date revised.

If we make material changes to the Privacy Policy, we will notify you through:

  • Notifications displayed in the application
  • Email notifications (if you have provided an email address)
  • Announcements posted on our website

12. Contact Us

If you have any questions, comments, or requests regarding this Privacy Policy, please contact us through:


13. Region-Specific Privacy Rights

13.1 EU Users (GDPR)

If you are located in the EU, under GDPR you have the following rights:

  • Right of Access: Obtain a copy of the data we hold about you
  • Right to Rectification: Correct inaccurate or incomplete data
  • Right to Erasure (Right to be Forgotten): Delete your data in certain circumstances
  • Right to Restriction of Processing: Restrict our processing of your data in certain circumstances
  • Right to Data Portability: Receive your data in a structured, commonly used, and machine-readable format
  • Right to Object: Object to data processing based on legitimate interests
  • Right to Withdraw Consent: Withdraw consent you previously gave

Note on Google Analytics: If you enable Google Analytics, your data will be processed by Google. You can exercise your rights regarding Google Analytics data through Google's privacy controls or by disabling analytics in Apiflow settings.

13.2 California Users (CCPA/CPRA)

If you are a California resident, under CCPA/CPRA you have the following rights:

  • Right to Know: Understand the categories and specific pieces of personal information we collect
  • Right to Delete: Request deletion of personal information we have collected
  • Right to Opt-Out: Opt out of the "sale" or "sharing" of personal information (we do not sell personal information)
  • Right to Non-Discrimination: Not be discriminated against for exercising privacy rights

Note on Google Analytics: Using Google Analytics may constitute "sharing" personal information under CCPA. You can opt out by disabling analytics in application settings.


14. Special Notes for Self-Hosted Deployments

If you choose to self-host Apiflow:

  • You have complete control over all data storage and processing
  • You are responsible for data security and backups
  • Terms in this Privacy Policy regarding our servers do not apply
  • You must comply with data protection laws applicable to you
  • We do not access any data in your self-hosted instance
  • Google Analytics integration is not applicable to self-hosted deployments

15. Data Minimization Principle

We follow the principle of data minimization:

  • Collect only necessary data
  • Retain data only for the required time
  • Use data only for specified purposes
  • Provide offline mode to maximize user privacy
  • Require explicit opt-in for analytics collection
  • Allow you to disable analytics at any time without affecting core functionality

Thank you for trusting Apiflow!

We are committed to protecting your privacy and continuously improving our privacy protection measures. If you have any questions or suggestions, please feel free to contact us.